Skip to main content

Vendor archive

qnap CVEs

Beta · best-effort

635 CVEs tagged to vendor qnap80 Critical, 167 High, 264 Medium, 124 Low, 0 Unrated.

CVE-2024-53695

Published Mar 7, 2025

A buffer overflow vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to modify memory or crash proces…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-53693

Published Mar 7, 2025

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability c…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53692

Published Mar 7, 2025

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50405

Published Mar 7, 2025

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability c…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50394

Published Mar 7, 2025

An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of t…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50390

Published Mar 7, 2025

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have already f…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48864

Published Mar 7, 2025

A files or directories accessible to external parties vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers to rea…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38638

Published Mar 7, 2025

An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gain…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-13086

Published Mar 7, 2025

An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23356

Published Dec 19, 2024

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27595

Published Dec 19, 2024

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53691

Published Dec 6, 2024

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained use…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50404

Published Dec 6, 2024

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50403

Published Dec 6, 2024

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-50402

Published Dec 6, 2024

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-50393

Published Dec 6, 2024

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbit…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-50389

Published Dec 6, 2024

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed t…

CVSS 9.5 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-50388

Published Dec 6, 2024

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We h…

CVSS 9.5 · Critical
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2024-50387

Published Dec 6, 2024

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-48868

Published Dec 6, 2024

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability c…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-48867

Published Dec 6, 2024

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 635 CVEsPage 11 of 26